#VU25799 Command Injection in IBM Spectrum Protect Plus - CVE-2020-4222
Published: March 6, 2020
IBM Spectrum Protect Plus
IBM Corporation
Description
The vulnerability allows a remote attacker to execute arbitrary commands on the target system.
The vulnerability exists within the Administrative Console Framework service due to improper validation of a user-supplied string in the "password" parameter before using it to execute a system call. A remote attacker can send a specially crafted HTTP command and execute arbitrary command on the system.